RSS   Podatności dla 'Datalife engine'   RSS

2010-05-20
 
CVE-2010-2005

CWE-94
 

 
Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the selected_language parameter to engine/inc/include/init.php, (2) the config[langs] parameter to engine/inc/help.php, (3) the config[lang] parameter to engine/ajax/pm.php, (4) and the _REQUEST[skin] parameter to engine/ajax/addcomments.php.

 
2009-03-06
 
CVE-2008-6406

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in admin.php in DataLife Engine (DLE) 7.2 allows remote attackers to inject arbitrary web script or HTML via the query string.

 


Copyright 2024, cxsecurity.com

 

Back to Top